Cybersecurity Audit Specialist

Mizuho Financial Group

Cybersec

Security

QA

About this role

The role plans and operates cybersecurity audits for Mizuho Financial Group and its group companies. Responsibilities include assessing governance and cybersecurity frameworks based on risk assessments and cyberattack scenarios, setting audit priorities, and preparing annual audit plans.

The auditor researches current cyberattacks, vulnerabilities, security-vendor and industry information, incident trends from monitoring tools such as EDR and SIEM, emerging threats, and response practices. The role evaluates the effectiveness of current measures, identifies issues, and incorporates findings into individual audits.

Day-to-day audit work includes interviews with operational personnel, reviews of system operation, verification of networks, access controls and vulnerability assessment processes, and reviews of SOC and CSIRT structures. The auditor evaluates exercises and incident-response processes, identifies root causes, recommends corrective actions and improvements, reports findings to management, and follows up after audits.

The position also contributes to continuous monitoring and the development of more advanced, risk-based audit practices. Activities include collecting and analyzing external developments and outage or incident information, defining audit scopes, identifying structural issues, responding to changes such as AI and new regulations, consolidating audit knowledge from domestic and overseas locations, and providing audits and advice that support management issues.

The internal audit group includes multiple teams beyond IT audit and works collaboratively on complex risks. The role may participate in organizational development, operational improvement, and other activities that strengthen the group.

Applicants must have experience in cybersecurity or IT audit, including internal audit at a financial institution or other business company, or external audit at an audit firm. Relevant areas include vulnerability management, SOC or CSIRT, risk management and governance, system configuration and implementation vulnerabilities, IT general controls, IT application controls, and information-security audits. Experience with cybersecurity audits is not mandatory when the applicant has IT control audit experience and wants to develop cybersecurity audit expertise. CIA, CISA or CISSP qualifications are preferred, as is experience in organizational management or management-oriented IT recommendations.

The position is full-time and permanent, with a six-month probationary period and the same salary during probation. The standard schedule is 8:40 to 17:10, with 7.5 working hours and a 60-minute break; flextime may apply depending on the department. The work location is Tokyo, and the company may change the work location, including locations where telework is performed. Weekends, public holidays and specified year-end and New Year holidays are off. Overtime or holiday work may be required. Salary is determined under company rules. Benefits include commuting and lunch subsidies subject to company rules, social insurance, an employee shareholding plan, childcare support, housing-related programs, asset-building support and leisure support.

This is an AI-generated summary of the employer's original posting — details can be incomplete, out of date or simply wrong. Always confirm everything on the official posting before applying.